MEDIUM
uri-js through 4.4.1 Improper UTF-8 Decoding via pctDecChars
Published Sep 18, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.40%
Description
uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platform decoder validation and inject path traversal or CRLF sequences that downstream consumers process without filtering.
Affected products
-
- Version 0StatusaffectedConstraints<=4.4.1
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://github.com/garycourt/uri-js product
- https://github.com/garycourt/uri-js/blob/a1acf730b4bba3f1097c9f52e7d9d3aba8cdcaae/src/uri.ts#L103-L141 technical-description
- https://github.com/garycourt/uri-js/issues/106 issue-tracking
- https://www.vulncheck.com/advisories/uri-js-through-4.4.1-improper-utf-8-decoding-via-pctdecchars third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/garycourt/uri-js | product | |
| https://github.com/garycourt/uri-js/blob/a1acf730b4bba3f1097c9f52e7d9d3aba8cdcaae/src/uri.ts#L103-L141 | technical-description | |
| https://github.com/garycourt/uri-js/issues/106 | issue-tracking | |
| https://www.vulncheck.com/advisories/uri-js-through-4.4.1-improper-utf-8-decoding-via-pctdecchars | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 18, 2026
Updated Sep 24, 2026
Reserved Sep 18, 2026
Link CVE-2026-93751
CISA Vulnrichment
Updated Sep 21, 2026